|
๐ซ๐ฎ
JimArchon72
|
|
2025/09/23 04:46:41 "GET /wp-login.php?wpaas-standard-login=1 HTTP/1.1"
|
Web App Attack
|
|
|
๐ฌ๐ง
[email protected]
|
|
Form spam attack on aydansfault.net detected on 2025-09-23
|
Brute-Force
|
|
|
๐ฌ๐ง
[email protected]
|
|
Form spam attack on aydansfault.net detected on 2025-09-23
|
Brute-Force
|
|
|
Anonymous
|
|
wordpress-trap
|
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 45.202.78.61 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 45.202.78.61 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 11 13:40:21.690461 2025] [security2:error] [pid 17584:tid 17584] [client 45.202.78.61:17359] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.intergalacticspir.mroxygen.org|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.intergalacticspir.mroxygen.org"] [uri "/s3cmd.ini"] [unique_id "aMMJhU8dkOWrDo2DSvFUAAAAAAQ"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 45.202.78.61 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 45.202.78.61 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 10 00:07:17.936468 2025] [security2:error] [pid 3624:tid 3624] [client 45.202.78.61:24241] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.hamson.com"] [uri "/config.php%7C/.env%7Csettings.py"] [unique_id "aMD5dZNUtqEjklioaihIfQAAAAo"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 45.202.78.61 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 45.202.78.61 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 06 18:03:02.533810 2025] [security2:error] [pid 25378:tid 25378] [client 45.202.78.61:38343] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.candidaboutcandida.banis-associates.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.candidaboutcandida.banis-associates.com"] [uri "/s3cmd.ini"] [unique_id "aLyvlgHNC7ObxFu1TmFUyAAAAAg"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 45.202.78.61 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 45.202.78.61 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 06 15:51:55.185365 2025] [security2:error] [pid 3449:tid 3449] [client 45.202.78.61:24459] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.alexscollay.com"] [uri "/config.php%7C/.env%7Csettings.py"] [unique_id "aLyQ24ppn_kMnTy9YL6snQAAAAU"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:225170) triggered by 45.202.78.61 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 45.202.78.61 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 14 04:33:32.180635 2025] [security2:error] [pid 32497:tid 32497] [client 45.202.78.61:23175] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||macromika.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "macromika.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aJ2fXBVbmYzehStWS3-aJgAAABI"], referer: https://www.google.com
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
Anonymous
|
|
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
|
Brute-Force
SSH
|
|
|
๐บ๐ธ
hostseries
|
|
Trigger: LF_DISTATTACK
|
Brute-Force
|
|
|
๐บ๐ธ
Anonymous
|
|
Brute force attack detected from 45.202.78.61
|
DDoS Attack
Brute-Force
Web App Attack
|
|
|
๐บ๐ธ
Anonymous
|
|
Brute force attack detected from 45.202.78.61
|
DDoS Attack
Brute-Force
Web App Attack
|
|
|
๐บ๐ธ
Anonymous
|
|
Brute force attack detected from 45.202.78.61
|
DDoS Attack
Brute-Force
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:225170) triggered by 45.202.78.61 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 45.202.78.61 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 12 08:13:35.927990 2025] [security2:error] [pid 2394990:tid 2394990] [client 45.202.78.61:44761] [client 45.202.78.61] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||st-johns.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "st-johns.us"] [uri "/wp-json/wp/v2/users"] [unique_id "Z4O__yJojokcQw_DTJgN-AAAAA8"], referer: https://www.google.com
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|